As someone that uses Cellebrite crap for work I find the Signal thing hilarious but also frustrating.
They already rolled out a big security patch (and disabled certain iPhone extraction features which I use). Frankly all the industry standard DFIR software is a mess but Cellebrite UFED is probably the worst. It’s 20 years of cell phone exploits duct taped together with open source tools and glue code.
The really frustrating bit is that the primary day to day use isn’t even encryption cracking or anything. It’s just to get tamper resistant copies or get data off of an unlocked device that Apple / Google have decided should be hard to get. If people actually had full access to their data it wouldn’t be worth it for my office to pay for a Cellebrite license. We used to pay for tools to copy various social media / webmail accounts, but now for most the first party export tools are considered sufficient.